36 lines
1.7 KiB
Markdown
36 lines
1.7 KiB
Markdown
---
|
|
status: open
|
|
opened: 2026-09-21
|
|
located-in: [mesh-host internal/apply (run-once marker), mesh-catalog modules/route-proxy]
|
|
---
|
|
|
|
# 077 — A fact fetched at first start is fetched once per declaration
|
|
|
|
## Symptom
|
|
|
|
A consumer fetches a fact its provider made at first start through a run-once step
|
|
([ADR 0098](../../02-DECISIONS/0098-a-fact-a-provider-makes-at-first-start-is-fetched-from-it.md)):
|
|
the route proxy fetches the certificate authority's root before it starts. The host runs a
|
|
run-once step once per declaration digest. When the authority is re-initialised — its state
|
|
wiped, or the module moved to another node, where it makes a new root — the proxy's declaration
|
|
is unchanged, so the step does not run again. The proxy keeps the old root, refuses the new
|
|
authority's certificates, and its own healing path, keyed on the root it holds, never fires.
|
|
|
|
Observed by reading the apply loop and the proxy, not from an incident. No bed re-keys an
|
|
authority.
|
|
|
|
## Why it matters beyond the instance
|
|
|
|
Any fact a provider makes at first start has the same shape: the consumer's declaration does not
|
|
change when the provider's fact does. A run-once step cannot say "again when the provider
|
|
changed", and a restart trigger is not allowed on a run-once step (ADR 0053), so there is no
|
|
declarative remedy today.
|
|
|
|
## What would close it
|
|
|
|
Either the run-once marker includes something of the provider's — the provider's declaration
|
|
digest, or an epoch the mesh raises when a provider is re-issued or moved — or the gate is not
|
|
run-once but a validator that runs before every start of the service and is cheap when nothing
|
|
changed. Decided, then proven by a bed that re-keys the authority and watches the proxy trust the
|
|
new root.
|